CVE-2026-20910

8.0

Copeland · XWEB Pro

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution by injecting malicious input into the firmware update action.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro devices allows authenticated attackers to achieve full remote code execution on affected systems.

Vulnerability

This vulnerability, classified as CWE-78, permits an authenticated attacker to inject arbitrary commands into the devices field during a firmware update process. The vulnerability requires the attacker to have high privileges to access the administrative update functions.

Business impact

The ability to execute arbitrary OS commands provides an attacker with total control over the affected industrial control system hardware. Given the CVSS score of 8.0, this represents a high risk of unauthorized access, potential modification of critical operational parameters, and a total compromise of the system availability. Such breaches can lead to significant operational downtime and safety risks in industrial environments.

Remediation

Immediate Action: Update the XWEB Pro firmware to the latest version by visiting the official Copeland software update portal or by using the system update menu directly from the device interface.

Proactive Monitoring: Review system access logs for unauthorized attempts to initiate firmware updates or suspicious modifications to the devices configuration field.

Compensating Controls: Restrict administrative access to the XWEB Pro interface to trusted management networks only, effectively limiting the potential pool of authenticated attackers who could trigger this flaw.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability poses a severe risk to the integrity and availability of Copeland XWEB Pro systems. Administrators must prioritize the deployment of the provided firmware update to remediate the command injection flaw. Given the potential for remote code execution, delaying this update significantly increases the exposure of the industrial environment to malicious actors.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.